Products provided by other business functions and their risks:
- Academic and Education
-
Academics and education software are used to create and manage educational classes, manage student rosters, teacher rosters, and facilitates in other administrative tasks.
Risks:
- Data exposure; including personal contact information and financial information.
- Disruption of business continuity, including loss of customer confidence.
- Application Framework
-
Web application frameworks are software systems that help standardize the way an organization's website works.
Risks:
- Disruption of business continuity; including loss of customer confidence and loss in revenue.
- Misuse of company assets, including the injection of malicious links or other code within the website.
- Change Management
-
Change Management service providers help organizations with software changes, office changes, automated application testing, and issue management.
Risks:
- Data exposure, including information on the inner workings and operation procedures of an organization.
- Disruption of business continuity, including loss in revenue.
- Construction / Industrial
-
Construction/Industrial management software is used for financial accounting, job scheduling, and reporting services in the industry.
Risks:
- Data exposure; including financial information, contract information, and contact information of employees.
- Disruption of business continuity, including loss in revenue.
- Electronic Data Exchange
-
Data exchange services are used to translate and manage data being transmitted and received in various formats between organizations.
Risks:
- Data exposure, including company data.
- Disruption of business continuity, including loss in revenue.
- GRC (Governance Risk Compliance)
-
Governance Risk Compliance software is used to help companies meet regulatory and compliance requirements.
Risks:
- Data exposure; including information into an organization’s security posture and weak areas of compliance.
- Disruption of business continuity; including loss of critical risk management information and event logs.
- Language
-
The language category encompasses natural languages used by services and products.
Risks: We have not determined any risk of a disruption or compromise in this set of services at this time.
- Legal and Professional Services
-
Legal and professional services software helps organizations manage and prepare documents and legal cases.
Risks:
- Data exposure; including financial information and sensitive information regarding legal case details.
- Disruption of business continuity, including loss of customer confidence and loss in revenue.
- Manufacturing / Engineering
-
Manufacturing and engineering management software helps organizations monitor system development, acquisitions, and project completions.
Risks:
- Data exposure; including budget data, information on the inner workings and operation procedures of an organization, scheduling information, and proprietary development information.
- Disruption of business continuity; including loss of customer confidence and loss in revenue.
- Mapping
-
Mapping providers deliver geographic or other map-based services.
Risks:
- Loss of customer confidence.
- Misuse of company assets.
- Medical / Healthcare
-
Medical and healthcare management software helps organizations send paper billing, track patients' schedules, and manage claims.
Risks:
- Data exposure; including organizational expenditures, payer credentials, and sensitive patient details (SSN and medical histories).
- Disruption of business continuity; including delayed claims, loss of information, loss of forms in transit, and loss in revenue.
- Mobile
-
Mobile software applies to applications used on phones and tablets.
Risks:
- Data exposure; including device information and inventories of installed software.
- Disruption of business continuity.
- Mobile Technologies
-
Mobile technologies are used by phone and tablet manufacturers to provide services to end users.
Risks:
- Disruption of business continuity.
- Misuse of company assets; including the injection of malicious links and the installation of potentially unwanted software.
- Nonprofit / Fund Management
-
A service that’s dedicated to furthering a particular social cause or advocating for a shared point of view. In economic terms, it is an organization that uses its surplus of the revenues to further achieve its ultimate objective, rather than distributing its income to the organization's shareholders, leaders, or members.
Risks: We are evaluating the impact of a disruption or compromise in this set of services.
- Performance Management
-
Performance management software is used to improve workplace productivity, efficiency, and measure progress over time.
Risks:
- Data exposure, including operational information and report history information.
- Disruption of business continuity, including loss of workplace performance analytic capabilities.
- Printing
-
This category includes printers and printer management software.
Risks:
- Disruption of business continuity depending on how heavily an organization relies on these services.
- Data exposure; including device information and areas of weakness.
- Property Management
-
Property management software is used to track property incomes, status, renter contact information.
Risks:
- Data exposure; including financial payment information, payment history, and contact details (personal and business).
- Disruption of business continuity, including loss in revenue.
- Quality Management
-
Quality management software is used to help organizations develop quality management systems for their processes.
Risks:
- Data exposure; including information on business thinking, business secrets, gaps in compliance coverage, and contact details of consultants.
- Disruption of business continuity; including loss of quality analytics and loss of compliance records.
- Reporting
-
Reporting software is used to create all kinds of human-readable reports using various sources of data.
Risks:
- Data exposure; including data sources, executive summaries, report contents, and histories.
- Disruption of business continuity, including loss of insight into business operations.
- Retail
-
Retail software is used to manage and provide point-of-sale systems to stores and retail chains.
Risks:
- Data exposure; including payment system information, customer credit information, and payment history.
- Disruption of business continuity; including loss in revenue and loss of retail insights.
- Search Engines
-
A service that assists organizations in optimizing their web presence and gaining exposure. This includes search engine optimization (SEO) services, search engine marketing (SEM) services, website promotion, and website optimization services.
Risks: We are evaluating the impact of a disruption or compromise in this set of services.
- SIEM (Security Information and Event Management)
-
Security information and event management software is used to aggregate and process multiple data streams, create reports, log events, and manage compliance.
Risks:
- Data exposure, including source data and information on confidential data streams.
- Disruption of business continuity, including loss of critical business insights, loss of security insights, and loss of report data.
- Server
-
Server software is used to run operating systems in which other services (database, web, etc.) are active.
Risks:
- Disruption of business continuity depending on how heavily an organization relies on the service, including loss in revenue.
- Misuse of company assets; including injection of malicious content, theft of data, or hijacking of other services.
- Service and Field Support
-
Service and field support software is used to track technical support staff and contractors, job status, parts, and contracts.
Risks:
- Data exposure; including client and contractor contact information, contractor whereabouts, purchase histories, and information on business interests.
- Disruption of business continuity, including loss of customer confidence.
- Shipping
-
Shipping software is used to create packing slips, track shipments, manage orders, and assist with billing.
Risks:
- Data exposure; including payment and logistics information.
- Disruption of business continuity, including loss in revenue.
- Sustainability / Green Enterprise
-
A service that facilitates in decreasing negative environmental impact, while providing improved social and environmental benefits to consumers and producers.
Risks: We are evaluating the impact of a disruption or compromise in this set of services.
- March 31, 2025: Published.
Feedback
0 comments
Please sign in to leave a comment.